DLP and UEBA are good technologies aimed at the wrong question. Both assume insider risk can be specified in advance. It cannot be, because the thing being detected is a person's intent, and intent does not appear in a policy or a baseline.
Contact us
You've made a great move. We'll be in touch shortly
I’ve spent most of my career watching security teams get better and better at detecting signals of something going wrong: an illicit data movement, rogue access, the early stages of sabotage, or even the presence of fake workers.
But even the best teams can fail to join these signals early enough to build a narrative of what is going on in time to stop the threat. By the time something blows up, the decisions that mattered were made weeks earlier.
Written for the insider risk problems teams actually have to answer for
The employee who is already leaving
What to watch for before a resignation lands, and how to act on it without accusing the wrong person.
IP and source code walking out
Where your crown jewels actually move, and which of those paths a program can realistically cover first.
The HR and legal case
How to build a timeline that survives a lawyer reading it, and who decides what happens next.
AI and shadow tools
Why banning the tools fails, and what a workable policy looks like when the workforce is already using them.
Contractors and third parties
Access you granted, governance you did not, and how to close that gap without stalling the business.
Every endgame starts with the right opening.
Most insider threats are preventable. The difference is how you develop your material.